CoreSpeed uses resources that exist at both the Cloudflare account level and the individual zone level.
Cloudflare account-level resources can include Workers, KV namespaces, account members, lists, and other shared configurations. Zone-level resources include DNS records, cache rules, WAF settings, redirects, and proxy configuration.
SiteCare-managed zone
When the zone is in SiteCare’s Cloudflare account:
- SiteCare remains responsible for CoreSpeed’s Workers, KV resources, routing, caching, and website delivery settings.
- The customer receives Administrator-level access to its zone.
- The customer has full DNS management capabilities for that zone.
- The customer does not receive access to unrelated SiteCare zones or account-wide CoreSpeed resources.
This keeps shared platform resources protected while still allowing the customer or its MSP to manage its DNS records.
Customer-owned account with O2O
For O2O, SiteCare requires the Cloudflare role named:
Super Administrator - All Privileges
Cloudflare defines this role as having access to all account settings, billing, account members, purchases, and account-owned API tokens.
This is intentionally broader than DNS-only or Domain Administrator access.
Under SiteCare’s current operating model, Super Administrator access is required so our team can configure and troubleshoot the account-level and zone-level resources involved in the CoreSpeed integration without encountering unknown permission gaps.
This is a SiteCare support requirement. It is not a claim that Cloudflare provides no granular permissions.
Cloudflare supports scoped roles and policies, but a limited combination of roles can leave SiteCare unable to investigate or correct an issue involving Workers, routes, account resources, certificates, or other parts of the request path.
Recommended governance
For customer-owned accounts:
- Invite named SiteCare users rather than sharing credentials.
- Require multifactor authentication.
- Notify SiteCare before changing Workers, cache rules, proxy settings, or website DNS records.
- Review access when CoreSpeed service ends.
- Maintain at least one internal Super Administrator.
Cloudflare recommends maintaining more than one Super Administrator so the organization is not dependent on a single user account.
Comments
0 comments
Please sign in to leave a comment.